Nz Privacy Act.
All posts.
Sending PII from Salesforce: Transport Encryption Is the Wrong Control
Encrypting the connection does not solve emailing personal information. What IPP 5 actually asks, and the pattern that keeps the data inside your control.
IPP 3A Is Live: Building New Zealand's Indirect-Collection Notice into Salesforce
New Zealand's IPP 3A now requires notice when you collect personal data indirectly. Build compliance into Salesforce with source fields, a Flow, one report.
Salesforce Data Sovereignty in New Zealand: There's No NZ Region, So What Actually Protects Your Data?
Salesforce has no New Zealand region, so your data sits offshore. What data residency, the US CLOUD Act, and NZISM actually mean for NZ gov and health orgs.
Why Salesforce Health Cloud Needs Its Own Security Review
Salesforce Health Cloud holds your most sensitive data, and the features that make it useful are the ones that expose it. What a security review checks.
Mapping Salesforce Security to NZISM, the NZ Privacy Act and ISO 27001
How to map Salesforce security findings to NZISM, the NZ Privacy Act, HISO 10029 and ISO 27001 using a source-verified, version-pinned control catalogue.